Lucene search

K
cvelistCertccCVELIST:CVE-2020-10124
HistoryAug 21, 2020 - 8:30 p.m.

CVE-2020-10124

2020-08-2120:30:39
CWE-311
CWE-306
CWE-353
certcc
www.cve.org
1
ncr selfserv atms
aptra xfs 05.01.00
security vulnerability
deposit forgery
physical access
arbitrary code
message integrity

AI Score

7.2

Confidence

High

EPSS

0.001

Percentile

46.0%

NCR SelfServ ATMs running APTRA XFS 05.01.00 do not encrypt, authenticate, or verify the integrity of messages between the BNA and the host computer, which could allow an attacker with physical access to the internal components of the ATM to execute arbitrary code, including code that enables the attacker to commit deposit forgery.

CNA Affected

[
  {
    "product": "SelfServ ATM",
    "vendor": "NCR",
    "versions": [
      {
        "status": "affected",
        "version": "APTRA XFS  05.01.00"
      }
    ]
  }
]

AI Score

7.2

Confidence

High

EPSS

0.001

Percentile

46.0%

Related for CVELIST:CVE-2020-10124